With the California Consumer Privacy Act (CCPA) taking effect on July 1, many businesses are reporting that they are not prepared to deal with the new data, including the European General Data Protection Regulation (GDPR). This is due, among other things, to a lack of staff to make the necessary changes, a lack of budget and resources, and a lack of understanding of how these privacy laws work. However, businesses should consider the importance of CCPA not so much in terms of privacy security as in terms of cybersecurity. The CCPA and other data privacy regulations could be a catalyst to help small and medium-sized businesses improve their overall cybersecurity posture.
Logan Kipp, CEO of SiteLock, said that even if small businesses don’t meet the CCPA compliance criteria, cybersecurity should be their priority. He added that cybercriminals typically target those who are least aware and prepared for such an attack, making unprepared businesses a much more attractive target.

According to Kipp, to mitigate risk, implementing comprehensive security tools and establishing a standard operating procedure for patching vulnerabilities, as well as training employees for greater cybersecurity awareness, will go a long way in helping organizations ensure their customers' personal information is safe.
Owners and decision-makers in small and medium-sized businesses often assume that they are not at risk from cyberattacks, since they are too small to be a target. Of course, this is not the case. On the contrary, in addition to targeted attacks, there are also random attacks, in which hackers consider data from both large companies and data from small and medium-sized businesses to be valuable.
Additionally, many comparisons are made between the CCPA and the GDPR, but the CCPA is slightly stronger than the GDPR when it comes to cybersecurity benefits. When third parties obtain data through another business , the CCPA requires them to provide explicit notice and an opportunity to opt out before reselling that personal information. Even for companies that are small enough not to be required to comply with the CCPA, Kipp recommended that they continue to take steps to comply with the regulation, as this will ensure they are better prepared for any future data breaches or security incidents . The CCPA is likely the first of many state-led privacy regulations, so similar regulations could be on the horizon for many. Now, small and medium-sized businesses can ensure they are well-prepared for any future regulations that might apply to them, as well as for future growth.

The pandemic has made data privacy regulations like GDPR and CCPA even more important as businesses are forced, if only temporarily, to transition from a traditional operating model to an e-commerce model. However, online businesses need to be protected and secured just like regular businesses. And that starts with being proactive about cybersecurity.
The point is that cybersecurity doesn't have to be scary or expensive. Little things like not reusing passwords, implementing multi-factor authentication (MFA), using a VPN , and training employees are good and important safeguards for large and small businesses.
Finally, when security is considered from a data privacy perspective, businesses must also implement reasonable security measures to protect their consumers’ personal information. To ensure they are compliant, small and medium-sized businesses should prepare to improve their privacy protections, as well as update privacy .
